CVE Vulnerabilities

CVE-2024-1725

Trust Boundary Violation

Published: Mar 07, 2024 | Modified: May 08, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Ubuntu

A flaw was found in the kubevirt-csi component of OpenShift Virtualizations Hosted Control Plane (HCP). This issue could allow an authenticated attacker to gain access to the root HCP worker nodes volume by creating a custom Persistent Volume that matches the name of a worker node.

Weakness

The product mixes trusted and untrusted data in the same data structure or structured message.

Affected Software

Name Vendor Start Version End Version
Red Hat OpenShift Container Platform 4.13 RedHat openshift4/kubevirt-csi-driver-rhel8:v4.13.0-202404200313.p0.g9d909f7.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.14 RedHat openshift4/kubevirt-csi-driver-rhel8:v4.14.0-202404161544.p0.g48fafc4.assembly.stream.el8 *
Red Hat OpenShift Container Platform 4.15 RedHat openshift4/kubevirt-csi-driver-rhel8:v4.15.0-202403220332.p0.gd3bdbce.assembly.stream.el8 *

References